What is phishing? How to spot fake bank emails, texts and calls
By SendPay Business · · 2 min read
Phishing is when a criminal pretends to be someone you trust, such as your bank, a delivery firm or a tax office, to trick you into handing over passwords, card details or security codes. It is one of the most common ways money accounts get broken into.
The three main kinds
Phishing usually means fake emails. Smishing is the same trick by text message, and vishing is by phone call. All three try to create panic or urgency so you act before you think.
Warning signs
- A message says your account is locked or a payment failed and asks you to act now.
- The link or sender address is slightly wrong when you look closely.
- You are asked for a full password, PIN or one-time code.
- A caller asks you to move money to a 'safe account'.
If you think you clicked
Change the password on the real site, contact your bank or card provider using the number on the back of your card, and watch your statements. In the UK you can forward scam texts to 7726 and scam emails to report@phishing.gov.uk.
Why strong authentication helps
Strong customer authentication asks for a second factor, such as a code or a fingerprint, so a stolen password alone is not enough. Genuine banks never ask you to read that code out to them.
Build it
Create your own financial platform.
Pick a template, name it, brand it, preview every page before you pay. Your brand, your users, your fees.
Build my platform →Questions people ask
What is strong customer authentication?
The two-step checks that block stolen passwords.
Strong authentication →Read next
This guide is general information, not legal or financial advice. SendPay Business is a technology company, not a bank, and does not take deposits; regulated services on the platforms are provided by licensed partners. PayPal, Patreon and Substack are named as reference points only and are not affiliated with SendPay Business.